I have a cluster of two CheckPoint 13000 appliances running R80.30.
Originally, on the internal side, they were connected to a core cluster of Cisco 6509 switches, each firewall connected to one of the two 6509 switches.
Just recently the core 6509 switches were replaced with a core cluster of Cisco Nexus 9500 switches, each firewall connected to one of the Nexus 9500 switches.
At the time of the replacement of 6509 switches with the 9500 switches, our average and peak connections almost doubled.
Whereas our previous normal peak would be 60K connections, our new peak became 100K connections, causing us to increase our concurrent connections max limit because of this unexpected increase.
Looking for any help in possible cause of this issue. Has anybody seen anything similar before, and what was the cause/fix?
Also trying to figure out how I can really tell what that increase in connections would be. What could I look for/at to determine what those roughly extra 40K of connections are in the firewall?
Thanks.
Quentin